Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Wazuh — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting Wazuh. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wazuh is an open-source security platform primarily utilized for intrusion detection, log data analysis, and compliance monitoring across diverse infrastructure environments. Its architecture integrates host-based agents with a central server to aggregate telemetry, enabling organizations to detect anomalies and maintain regulatory adherence. Historically, the software has been associated with vulnerabilities such as remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or improper access controls within its web interface and API components. With thirty-nine recorded CVEs, these issues highlight risks related to authentication bypasses and insecure default configurations. While no catastrophic breaches have been publicly attributed directly to Wazuh itself, the frequency of these CVEs underscores the importance of rigorous patch management and secure deployment practices to mitigate potential exploitation vectors in enterprise security operations.

Found 1 results / 65Clear Filters
High2026-08-20
fix(fim): use parameterized queries for FIM DB path lookups · wazuh/wazuh@8e4e25b · GitHub
High2026-08-20
Migrate FIM DB path queries to parameterized statements by Darioortegaleyva · Pull Request #36399 · wazuh/wazuh · GitHub
Medium2026-08-20
Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd · Advisory · wazuh/wazuh · GitHub
Unknown2026-08-20
Release Wazuh v4.14.6 · wazuh/wazuh · GitHub
Critical2026-08-20
Validate current user in update-user endpoint by vikman90 · Pull Request #35442 · wazuh/wazuh · GitHub
HighCVE-2025-414242026-08-20
Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint · Advisory · wazuh/wazuh · GitHub
High2026-08-20
Backport: Validate current user in update-user endpoint to 4.10.4 by vikman90 · Pull Request #35469 · wazuh/wazuh · GitH
High2026-08-20
fix: validate current user in update-user endpoint · wazuh/wazuh@1a38d11 · GitHub
High2026-08-20
Merge pull request #35442 from wazuh/fix/4526-api-update-user · wazuh/wazuh@813add3 · GitHub
High2026-08-20
Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V:
High2026-08-20
Release Wazuh v4.10.4 · wazuh/wazuh · GitHub
High2026-08-20
fix: ensure NUL-termination in compare_wazuh_versions string buffers · wazuh/wazuh@b6aac37 · GitHub
CriticalGHSA-r6f5-h662-8f8c2026-08-20
cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path inje
High2026-08-20
Improve tmp_file path validation in cluster DAPI by vikman90 · Pull Request #36246 · wazuh/wazuh · GitHub
High2026-08-20
fix(cluster): tmp_file path validation · wazuh/wazuh@de1eeed · GitHub
Critical2026-08-20
merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager · Adviso
High2026-08-20
Improve cluster merged file parameter validation by vikman90 · Pull Request #36204 · wazuh/wazuh · GitHub
High2026-08-20
fix(cluster): validate merge file parameters to prevent directory escape · wazuh/wazuh@88fc89f · GitHub
CriticalCVE-2025-434412026-08-20
peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH
Unknown2026-08-20
Cluster file processing parameter validation by vikman90 · Pull Request #36296 · wazuh/wazuh · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with Wazuh. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.